If you have been trying to follow US state AI laws through headlines, you have whiplash by now, and mid-2026 made it worse: Colorado, whose 2024 act was the model everyone benchmarked against, repealed and replaced it before it ever took effect. Here is the honest orientation: there is no single US AI law, the patchwork is real, and yet the practical burden for a startup concentrates in two places that have stayed stable while the statutes churned: consequential decisions about people, and honesty with consumers about AI. Map those two, and the patchwork gets much less frightening.
This guide walks the Colorado story (because it explains the direction of travel), the rules actually in effect now, the pattern underneath them, and the short list worth doing this quarter. It is the US companion to does the EU AI Act apply to your US startup.
Colorado: the bellwether that blinked
Colorado's SB 24-205, enacted in 2024, was the first comprehensive state AI act: a risk-based framework targeting algorithmic discrimination in "high-risk" AI systems used in consequential decisions (employment, housing, health care, education, and similar), with duties of care for developers and deployers, impact assessments, risk-management programs, and attorney-general reporting. It was scheduled to take effect in 2026, first February, then delayed to June 30.
It never got there. Facing sustained pressure that the framework would bury startups in administrative burden, Colorado's legislature passed, and in May 2026 the governor signed, a repeal-and-replace: the revised law eliminates the duty-of-care and impact-assessment architecture and refocuses on disclosure and transparency around certain automated decision systems, now effective January 1, 2027. Whatever the final details look like when guidance arrives, the direction matters more than the statute: even the most ambitious state pulled back from EU-style process obligations toward disclosure duties, and every other legislature watched it happen.
Which state AI laws are in effect right now
- Texas (TRAIGA), effective January 1, 2026. The Responsible AI Governance Act centers on prohibited uses (manipulation, certain biometric identification, social scoring, unlawful discrimination) with significant government-use provisions, plus a regulatory sandbox. Its practical reach for most private startups is narrower than headlines suggested, but the prohibited-use list is worth reading once against your roadmap.
- Illinois, effective January 1, 2026. Amendments to the state Human Rights Act govern AI in employment decisions: using AI in a way that discriminates, or using zip codes as a proxy for protected classes, is a civil-rights violation, and employees must be notified when AI is used in employment decisions. If your product touches hiring, promotion, or scheduling for Illinois workers, this applies to your customers, which means it applies to your contracts.
- New York City, in force since 2023. Local Law 144 requires bias audits and candidate notice for automated employment decision tools used on NYC candidates. It remains the operational template for what employment-AI compliance looks like in practice.
- California's cluster. Regulations on automated decision-making technology (ADMT) under the state privacy law were finalized in 2025 and phase in through the coming years, adding notice, opt-out, and access rights around significant automated decisions. Alongside them: training-data transparency requirements for generative AI developers and content-provenance obligations, plus a frontier-model safety statute aimed at the largest developers.
- Utah and the disclosure family. Utah requires clear disclosure when consumers interact with generative AI in certain contexts, and a growing set of states regulates specific interactions: companion chatbots, healthcare AI communications, and impersonation. The common thread is simple honesty: tell people when they are talking to a machine.
Regulators keep converging on two questions: does your AI decide things about people, and do people know they are dealing with AI? Answer those well and most of the patchwork follows.
The pattern underneath the patchwork
Strip the statute names and the pattern is consistent. First, consequential decisions. AI that influences employment, credit, housing, insurance, health care, or education triggers the heaviest obligations everywhere: bias concerns, notice, sometimes audits, sometimes human-review rights. This mirrors the EU's high-risk category, and it is the same lens investors and enterprise customers apply in procurement diligence. Second, disclosure. Consumer-facing AI attracts transparency duties: disclose the interaction, label synthetic content where required, be honest about capabilities. Existing law fills the rest: deceptive-practices statutes, discrimination law, and privacy law all apply to AI without needing the letters A and I in the title.
What a lean startup should actually do this quarter
- Inventory the consequential-decision touchpoints. Where does your product influence decisions about people's jobs, money, housing, health, or education, directly or through customers? That list is your real exposure map, and it feeds the same records an enterprise buyer will request.
- Add honest AI disclosures. If consumers interact with your AI, say so plainly in the product. It satisfies the Utah-style statutes, aligns with FTC expectations, and costs a sentence.
- Keep decision records. For anything on the consequential list, be able to explain what the system considers and how outcomes are reviewed. Colorado's replacement law, California's ADMT rules, and NYC's audit regime all reward the same artifact: a written account of how the automated decision works.
- Push clarity into contracts. If customers deploy your AI into regulated decisions, your terms should allocate who handles notices, audits, and compliance, which is the same conversation as your model-provider terms upstream.
- Date-stamp your compliance beliefs. This area changed twice while this article was being researched. Whatever you concluded last year about Colorado is wrong now; whatever you conclude today needs a revisit date.
- No single US AI law exists; the patchwork is state statutes plus existing law applied to AI.
- Colorado repealed and replaced its landmark act in May 2026: narrower, disclosure-focused, effective January 1, 2027. The direction of travel is away from EU-style process burdens.
- In effect now: Texas TRAIGA and Illinois employment-AI rules (January 2026), NYC's bias-audit law, Utah-style disclosure duties, and California's ADMT and transparency cluster.
- The stable pattern: heavy duties where AI touches consequential decisions about people; disclosure duties where consumers interact with AI.
- Do four things: inventory decision touchpoints, disclose AI interactions, keep decision records, and allocate compliance in contracts. Then re-verify quarterly.
The strategic read: state AI law is volatile in its details and stable in its direction. Startups that build the two disciplines the pattern rewards, decision records and honest disclosure, will find each new statute mostly asks for what they already have. Startups that wait for the patchwork to settle will be waiting for a while.
Related reading: the EU AI Act for US startups, the AI startup legal checklist, and privacy policies and terms of service. Or start a conversation about your exposure map.